Firmware Vulnerability in Botslab G980H Dash Camera
CVE-2026-79959
7HIGH
What is CVE-2026-79959?
The Botslab G980H dash camera is affected by a vulnerability within its firmware that features a hard-coded root account password. This password is immutable by the user, creating a significant security concern. If an attacker gains access to the firmware or has physical possession of the device, they could retrieve the hard-coded credentials. This access allows unauthorized users to gain root-level control via the UART interface, potentially compromising device integrity and user privacy.
Affected Version(s)
G980H 30010_QHG980HN5294SysFW+
G980H 58_QHG980HMCN5291SysFW+
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Julian of Software Secured reported this vulnerability to CISA.
